CVE-2020-24186
85Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 10epss 95%
from disclosure to weapon287 days
Published on NVDAug 24
1st PoC+287d
metasploitFeb 21
exploitation probability
95%top 1% of all CVEs
observed exploitation
nono source reports it
11 public exploit(s)
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
Affected products
n/a · n/apublic PoCs found — 11
exploitdbwww.exploit-db.com/exploits/49967unverifiedexploitdbwww.exploit-db.com/exploits/49962unverifiedgithubgithub.com/hev0x/CVE-2020-24186-wpDiscuz-7.0.4-RCE★ 19githubgithub.com/substing/CVE-2020-24186_reverse_shell_upload★ 13githubgithub.com/Sakura-501/CVE-2020-24186-exploit★ 3githubgithub.com/meicookies/CVE-2020-24186★ 0githubgithub.com/GazettEl/CVE-2020-24186★ 0githubgithub.com/sec-dojo-com/CVE-2020-24186★ 0cve_referencepacketstormsecurity.com/files/162983/WordPress-wpDiscuz-7.0.4-Shell-Upload.htmlunverifiedcve_referencepacketstormsecurity.com/files/163302/WordPress-wpDiscuz-7.0.4-Shell-Upload.htmlunverifiedcve_referencepacketstormsecurity.com/files/163012/WordPress-wpDiscuz-7.0.4-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/162983/WordPress-wpDiscuz-7.0.4-Shell-Upload.htmlhttp://packetstormsecurity.com/files/163012/WordPress-wpDiscuz-7.0.4-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/163302/WordPress-wpDiscuz-7.0.4-Shell-Upload.htmlhttps://www.wordfence.com/blog/2020/07/critical-arbitrary-file-upload-vulnerability-patched-in-wpdiscuz-plugin/